A vulnerability, which was classified as problematic, has been found in HTMLy 3.1.1. Affected by this vulnerability is an unknown functionality of the file /add/content?type=image. Performing a manipulation results in cross site scripting.

This vulnerability is reported as CVE-2026-38949. The attack is possible to be carried out remotely. No exploit exists.